Multi-Actor Espionage Campaign Weaponizes Balochistan Police Complaint Management Portal (PlugX, ShadowPad, Cobalt Strike, Remcos/TAG-179) — Threadlinqs Intelligence
As of 2026-07-11, Multi-Actor Espionage Campaign Weaponizes Balochistan Police Complaint Management Portal (PlugX, ShadowPad, Cobalt Strike, Remcos/TAG-179) is a high-severity apt threat attributed to TAG-179 (China / India), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 43 indicators of compromise.
Threat ID: TL-2026-1239 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: TAG-179 · China / India · ESPIONAGE
SentinelLABS documented converging China-nexus (PlugX, ShadowPad, Cobalt Strike) and India-nexus (TAG-179/Remcos, overlapping Mysterious Elephant/APT-C-08/SideWinder/Confucius/Bitter TTPs) espionage
SentinelOne's SentinelLABS (researcher Aleksandar Milenkoski) published "One Target, Two Flags: Rival Espionage Actors Converge On Pakistani Law Enforcement," documenting a multi-year, multi-actor cyberespionage campaign against Pakistani police infrastructure. Two distinct, unrelated nation-state-nexus actor clusters independently compromised overlapping victim infrastructure: a suspected China-nexus cluster deploying PlugX (Feb 27-Sep 28, 2024), ShadowPad (Nov 5-Dec 1, 2024), and Cobalt Strike (Oct 12, 2024-Dec 2025); and a suspected India-nexus cluster tracked by Recorded Future as TAG-179, overlapping with Kaspersky's Mysterious Elephant (APT-K-47/APT-C-08) and related SideWinder/Confucius/Bitter TTP-sharing groups, deploying Remcos RAT (Jan 13-Apr 9, 2026) via a decoy document themed around Afghan Citizen Card (ACC) repatriation operations.
The most significant new development is the China-nexus actor's compromise of the Balochistan Police Complaint Management System (CMS), a public-facing web application at cms.balochistanpolice.gov.pk that is used both by police staff (restricted ps-[district] logins) and by ordinary citizens filing complaints. The attackers uploaded two variants of a custom implant named cms_plugin.exe to the portal's client-scripts directory, disguised as a routine portal update: a Rust-based stager and a .NET executable masquerading as the legitimate Chinese antivirus process 360Safe.exe (Qihoo 360). The .NET variant reflectively loads an embedded AsyncRAT client that calls back to 41.216.188.140. Compromised Chinese-language PDB paths (D:\codedome\case\six\Client\Client2\obj\Debug\Client2.pdb), the term "xinshi" (new variant), and Simplified Chinese log strings indicate a Chinese-speaking developer.
Beyond the CMS, the China-nexus actors compromised Balochistan Police web servers hosting the First Information Report (FIR) system, the Human Resource Management Information System (HRMIS), the Anti-Vehicle Lifting System (AVLS), HotelEye (hotel/tenant tracking with NADRA national-ID integration), the Criminal Record Management System (CRMS, biometric records), the Tenant Registration System (TRS), two network appliances, and a Fortinet FortiMail email gateway appliance — all part of an EU-supported "Smart Police Station" digitalization initiative that was turned into an intelligence-collection vector.
SentinelLABS assesses with high confidence that the China-nexus activity is motivated by Beijing's concern for the safety of Chinese nationals connected to the China-Pakistan Economic Corridor (CPEC), following deadly attacks on Chinese personnel including the October 2024 Karachi airport bombing and a March 2024 suicide bombing, both attributed to the Balochistan Liberation Army (BLA); China sought independent insight into Pakistan's internal security posture ahead of a January 2026 China-Pakistan counterterrorism coordination agreement. The India-nexus/TAG-179 activity is assessed as driven by the long-running India-Pakistan security rivalry and interest in Balochistan's insurgency dynamics and cross-border militancy dynamics. Victimology for the broader PlugX/ShadowPad/Cobalt Strike and TAG-179/Mysterious Elephant clusters spans government, foreign affairs, defense, intelligence, academic/research, telecommunications, NGO, and manufacturing targets across South Asia (India, Bangladesh, Nepal, Sri Lanka), Southeast Asia (Vietnam, Thailand, Philippines), Central Asia (Kazakhstan, Tajikistan), East Asia (China, Taiwan — including Tibetan Buddhist organizations), the Middle East/Arabian Peninsula (Saudi Arabia, UAE, Iran), and Southeast Europe.
No CVEs were disclosed in the source reporting; initial access to the CMS and internal networks appears to rely on compromised credentials, direct web-application upload access, and trust in a public-facing government portal rather than a specific software vulnerability.
Weaknesses (CWE)
CWE-506, CWE-829, CWE-345
Target sectors: government administration, police - law enforcement, defense, foreignaffairs, intelligence, academicresearch, telecoms, ngo, manufacturing, criticalinfrastructure
Target regions: pakistan, South Asia, Southeast Asia, 143 - Central Asia, East Asia, Middle East, Southeast Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 43 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, HIGH, threat intelligence, cybersecurity, T1591, T1587.001, T1583.004, T1199, T1566.001, T1189, T1078, T1204.002, T1106, T1059